AI-driven cryptography analysis reveals vulnerabilities in post-quantum signature scheme HAWK and reduced AES variant
On July 28, 2026, Anthropic’s Frontier Red Team published research highlighting cryptographic weaknesses discovered using an internal preview of their Mythos model. While the findings do not pose immediate threats to current systems, they underscore emerging challenges in cryptographic security as artificial intelligence tools advance.
Post-quantum hawk takes a rare dive
HAWK, a post-quantum signature scheme designed for quantum resistance, had successfully passed two rounds of expert evaluation over two years as part of the NIST’s post-quantum cryptography standardization process. Recent analysis using Anthropic’s Mythos model revealed a critical vulnerability that reduces the effective security of HAWK-256 from 2⁶⁴ to just 2³⁸ operations.
The attack exploits a geometric symmetry in the Euclidean lattice isomorphism problem that underpins HAWK’s security. By reducing the lattice dimension by half, researchers achieved a full key recovery in 3 hours and 42 minutes on a standard 96-core server. This breakthrough led the HAWK team to withdraw the algorithm from the NIST selection process on July 29, effectively ending its candidacy.
For context, doubling key sizes to restore security would compromise HAWK’s primary advantage—its computational efficiency compared to other post-quantum candidates.
Reduced AES variant falls to AI-enhanced cryptanalysis
The research also examined a weakened variant of AES-128, reduced to 7 rounds instead of the standard 10. While this version holds no practical significance, it serves as an important academic benchmark. Anthropic’s team developed the “Möbius Bridge” technique, an invariant fingerprinting approach integrated into a meet-in-the-middle attack that eliminates 256 exhaustive search iterations.
The innovation accelerates cryptanalysis by factors of 200 to 800 compared to previous methods published in 2013. However, the three additional rounds in standard AES-128 render such attacks infeasible in real-world applications. French cybersecurity agency ANSSI continues to recommend AES-192 or AES-256 for post-quantum security scenarios.
Research methodology and computational costs
The discoveries required significant computational resources. The HAWK analysis consumed approximately 60 hours of autonomous computation at an estimated API cost of $100,000. Notably, the initial Mythos preview refused to execute the requested tasks on the reduced AES variant, asserting that no improvements were possible on such a well-established algorithm. After adjusting the scaffolding instructions, the model generated approximately one billion tokens over several days to develop the new attack methodology.
All findings underwent rigorous validation by two researchers over a one-month period to ensure mathematical rigor and eliminate potential hallucinations. The process involved verifying every equation, algebraic transformation, and complexity reduction proposed by the AI model.
Broader implications for cybersecurity
While these discoveries have no immediate impact on deployed systems, they highlight a critical shift in the cybersecurity landscape. The primary bottleneck has moved from finding vulnerabilities to validating AI-generated cryptanalysis results. The HAWK case required approximately one week of conceptualization followed by a month of verification by two researchers—demonstrating that human expertise remains essential despite AI capabilities.
The research also revealed that AI models may initially resist exploring certain cryptographic challenges, requiring careful scaffolding to achieve breakthroughs. This suggests that human guidance remains crucial in directing AI-driven security research.
As AI tools continue to evolve, the cybersecurity community must adapt to this new paradigm where computational power combines with human expertise to push the boundaries of cryptographic analysis.
More Stories
Ai breakthrough cracks AES encryption flaws in controlled test
Cameroun : quels moyens numériques sécurisés pour permettre au président Paul Biya de travailler à distance ?
Gabon’s digital leap: how satellite tech is reshaping national connectivity